CVE-2026-88279: GV-LPC2011/LPC2211 - ONVIF CreateUsers Username/Password Stack-Frame Overflow Denial of Service
Published Sep 10, 2026
·Updated
GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allowing an authenticated administrator to crash the ONVIF worker.
Affected Software
1 affected component
GeoVision GV-LPC2011/LPC2211=V1.13
Event History
Sep 10, 2026
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs authenticated administrator access to the affected device's ONVIF CreateUsers functionality. The provided data does not indicate that unauthenticated users can exploit it.
2
What is the impact of successful exploitation?
Oversized username or password values can crash the ONVIF worker, causing a denial of service. No confidentiality or integrity impact is identified in the supplied severity vector.
3
Which version is identified as affected?
The supplied information specifically identifies GeoVision GV-LPC2211 V1.13. Although the product listing includes GV-LPC2011/LPC2211, no affected GV-LPC2011 version is provided.